AUTO-UPDATED

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are actively exploiting a critical remote code execution vulnerability in the WooCommerce Wholesale Lead Capture plugin, while separate flaws threaten users of The Events Calendar.

Key Points

  • The WooCommerce Wholesale Lead Capture vulnerability, tracked as CVE-2026-27540, allows unauthenticated attackers to upload malicious PHP files via the "wwlc_file_upload_handler" AJAX action.
  • Wordfence has blocked over 100,000 exploit attempts targeting the WooCommerce plugin, which affects all versions up to 2.0.3.1.
  • The Events Calendar plugin, used by over 600,000 websites, contains two critical remote code execution flaws, CVE-2026-78159 and CVE-2026-78006.
  • Exploitation of The Events Calendar vulnerabilities can lead to full site takeover, password resets, and arbitrary command execution on the underlying server.
  • Developers have released patches for both plugins, and administrators are urged to update immediately to secure their WordPress environments.

Why it Matters

These vulnerabilities pose a severe risk to website integrity, as they allow unauthenticated attackers to gain full control over compromised WordPress servers. Failure to patch these plugins could result in significant data theft, malware distribution, and the permanent loss of administrative access for site owners.
Internet Published by info@thehackernews.com (The Hacker News)
Read original